Threagile | DefectDojo Documentation

Threagile

File Types

DefectDojo parser accepts a .json file.

JSON reports are created from the Threagile tool (default name risks.json) using the following command:

docker run --rm -it -v "$(pwd)":/app/work threagile/threagile -verbose -model /app/work/threagile.yaml -output /app/work

Acceptable JSON Format

Parser expects an array of findings. All properties are strings. Required fields are the following

category field is used to set both the title of the Finding as well as the CWE. most_relevant_technical_asset field is used to determine the component.

[
    {
        "category": "unguarded-direct-datastore-access",
        "risk_status": "unchecked",
        "severity": "elevated",
        "exploitation_likelihood": "likely",
        "exploitation_impact": "medium",
        "title": "<b>Unguarded Direct Datastore Access</b> of <b>PoliciesRegoStorage</b> by <b>Energon</b> via <b>EnergonToPolicyRegoFileStorage</b>",
        "synthetic_id": "unguarded-direct-datastore-access@energon-ta>energontopolicyregofilestorage@energon-ta@policies-rego-storage-ta",
        "most_relevant_data_asset": "",
        "most_relevant_technical_asset": "policies-rego-storage-ta",
        "most_relevant_trust_boundary": "",
        "most_relevant_shared_runtime": "",
        "most_relevant_communication_link": "energon-ta>energontopolicyregofilestorage",
        "data_breach_probability": "improbable",
        "data_breach_technical_assets": [
            "policies-rego-storage-ta"
        ]
    },
    {
        "category": "unguarded-direct-datastore-access",
        "risk_status": "in-discussion",
        "severity": "elevated",
        "exploitation_likelihood": "likely",
        "exploitation_impact": "medium",
        "title": "<b>Unguarded Direct Datastore Access</b> of <b>PoliciesRegoStorage</b> by <b>IAMSidecar</b> via <b>IAMBachendAPIPoliciesRegoFileStorage</b>",
        "synthetic_id": "unguarded-direct-datastore-access@iam-sidecar-ta>iambachendapipoliciesregofilestorage@iam-sidecar-ta@policies-rego-storage-ta",
        "most_relevant_data_asset": "",
        "most_relevant_technical_asset": "policies-rego-storage-ta",
        "most_relevant_trust_boundary": "",
        "most_relevant_shared_runtime": "",
        "most_relevant_communication_link": "iam-sidecar-ta>iambachendapipoliciesregofilestorage",
        "data_breach_probability": "improbable",
        "data_breach_technical_assets": [
            "policies-rego-storage-ta"
        ]
    },
    {
        "category": "unguarded-direct-datastore-access",
        "risk_status": "accepted",
        "severity": "elevated",
        "exploitation_likelihood": "likely",
        "exploitation_impact": "medium",
        "title": "<b>Unguarded Direct Datastore Access</b> of <b>PoliciesRegoStorage</b> by <b>IDMSidecar</b> via <b>IAMSidecarPoliciesRegoFileStorage</b>",
        "synthetic_id": "unguarded-direct-datastore-access@idm-sidecar-ta>iamsidecarpoliciesregofilestorage@idm-sidecar-ta@policies-rego-storage-ta",
        "most_relevant_data_asset": "",
        "most_relevant_technical_asset": "policies-rego-storage-ta",
        "most_relevant_trust_boundary": "",
        "most_relevant_shared_runtime": "",
        "most_relevant_communication_link": "idm-sidecar-ta>iamsidecarpoliciesregofilestorage",
        "data_breach_probability": "improbable",
        "data_breach_technical_assets": [
            "policies-rego-storage-ta"
        ]
    },
    ...
]

Sample Scan Data

Sample Threagile scans can be found here.

Default Deduplication Hashcode Fields

By default, DefectDojo identifies duplicate Findings using these hashcode fields: